SAA-C03 study guide: domains, format and a 6-week plan
· 8 min read
SAA-C03, the AWS Certified Solutions Architect – Associate exam, tests whether you can design AWS solutions that are secure, resilient, high-performing and cost-optimised, based on the AWS Well-Architected Framework. Almost every question describes a business requirement and asks which architecture meets it best. You sit 65 questions in 130 minutes, at a Pearson VUE test centre or online.
SAA-C03 at a glance
| Provider | Amazon Web Services |
| Level | Associate |
| Questions | 65 (50 scored, 15 unscored) |
| Duration | 130 minutes |
| Passing score | 720 on a scale of 100–1,000 |
| Exam fee (USD) | $150 |
| Languages | English, French (France), Italian, Japanese, Korean, Portuguese (Brazil), Spanish (Latin America), Spanish (Spain), Simplified Chinese, Traditional Chinese |
| Delivery | Pearson VUE test centre or online proctored |
| Question formats | Multiple choice, multiple response |
Details as of September 2026 — confirm on the official exam page before booking.
AWS has announced that the Italian version of the exam retires after 31 December 2026, so if you plan to sit in Italian, check the page before scheduling. The certification is valid for three years.
Who this exam is for
The exam guide describes the target candidate as someone with at least one year of hands-on experience designing cloud solutions that use AWS services. AWS also notes that candidates with one to three years of general IT experience have prepared for and earned it, and that people with no IT work experience would benefit from taking the [Cloud Practitioner exam](/blog/clf-c02-study-guide) first. There is no formal prerequisite.
The exam does not require deep coding skill. What it does require is breadth: you need to know dozens of services well enough to choose between them under constraints such as "lowest cost", "least operational overhead" or "no application changes".
What the exam covers
The exam guide has four domains, each named after a Well-Architected pillar. The domains overlap: one database question can test resilience, performance and cost at once.
Domain 1: Design Secure Architectures (30%)
This domain covers secure access to AWS resources, secure workloads and applications, and data security controls. Expect questions on IAM users, groups, roles and policies; cross-account access through AWS STS and role switching; multi-account governance with AWS Control Tower and service control policies; and when to federate a directory through IAM Identity Center. On the network side, you need security groups versus network ACLs, public and private subnets, NAT gateways, and connecting on-premises networks through VPN or AWS Direct Connect. Data protection means AWS KMS for encryption at rest, ACM certificates for TLS in transit, key policies and rotation, and backups and replication. The judgement being tested is least privilege: the right answer grants exactly what is needed, usually through a role rather than stored credentials, and keeps secrets in AWS Secrets Manager rather than in code.
Domain 2: Design Resilient Architectures (26%)
Two tasks: scalable, loosely coupled architectures, and highly available or fault-tolerant ones. The first asks you to decouple components with Amazon SQS and publish/subscribe messaging, use API Gateway, Lambda and Fargate for serverless designs, orchestrate workflows with AWS Step Functions, and choose between Amazon ECS and Amazon EKS for containers. The second is about Multi-AZ and multi-Region design, Route 53 failover, removing single points of failure, RDS Proxy, and the four disaster recovery strategies — backup and restore, pilot light, warm standby and active-active — matched to a stated RPO and RTO. A recurring theme is improving the reliability of legacy applications when the code cannot change, which usually points to infrastructure answers such as load balancers, Auto Scaling groups and managed databases.
Domain 3: Design High-Performing Architectures (24%)
Five tasks: storage, compute, databases, networking, and data ingestion. You need to choose between Amazon S3, EFS and EBS (object, file and block storage) and pick the right EBS volume type; select EC2 instance families, size Lambda memory and set scaling metrics; match workloads to Amazon Aurora, DynamoDB or RDS, and add read replicas or ElastiCache for read-heavy traffic; and pick CloudFront or AWS Global Accelerator at the edge. The data task covers Amazon Kinesis for streaming, AWS Glue for transformation (for example CSV to Parquet), Athena for querying data in S3, Lake Formation for data lakes, and DataSync or Storage Gateway for moving data in. The skill tested is reading the access pattern in the scenario — read-heavy or write-heavy, streaming or batch, shared or single-instance — and matching it.
Domain 4: Design Cost-Optimized Architectures (20%)
This domain revisits storage, compute, databases and networks with cost as the deciding factor. Know the S3 storage classes and lifecycle policies, HDD versus SSD EBS volumes, and the cheapest way to move data to AWS. For compute, know when Spot Instances, Reserved Instances or Savings Plans fit, and which load balancer (Application, Network or Gateway) a scenario needs. For networking, learn what drives data transfer cost: cross-AZ and cross-Region traffic, NAT gateways (one shared versus one per AZ), VPC endpoints, Transit Gateway versus VPC peering. Know Cost Explorer, AWS Budgets, the Cost and Usage Report and cost allocation tags.
A 6-week study plan
SAA-C03 covers many services, so six weeks of steady study is a sensible default. The plan follows the weights and leaves the final week for full mocks.
Week 1: foundations and identity. Regions, Availability Zones, the shared responsibility model, and IAM in depth: policies, roles, STS, cross-account access, Organizations and SCPs, IAM Identity Center. Write a few policies in a personal AWS account and test what each allows. End with a Domain 1 paper.
Week 2: networking and data security. Build a VPC with public and private subnets, route tables, a NAT gateway, security groups and network ACLs. Study VPN, Direct Connect, VPC endpoints and PrivateLink, then KMS, ACM, Secrets Manager, AWS WAF, AWS Shield, GuardDuty and Macie. Finish Domain 1 with a mixed paper and review every explanation.
Week 3: resilience. Decoupling with SQS and SNS, serverless with Lambda and API Gateway, containers with ECS, EKS and Fargate, Step Functions. Then high availability: Elastic Load Balancing, Auto Scaling, Multi-AZ databases, Route 53 routing policies and the four DR strategies. Take a Domain 2 paper.
Week 4: performance. Storage (S3, EFS, EBS, FSx), compute choices, databases (RDS, Aurora, DynamoDB, ElastiCache, RDS Proxy) and edge services (CloudFront, Global Accelerator). Add the data-ingestion services: Kinesis, Glue, Athena, Lake Formation, DataSync and Storage Gateway. Take topic papers per area and a mixed Domain 3 paper.
Week 5: cost. S3 storage classes and lifecycle rules, EC2 purchasing options, instance right-sizing, NAT and data transfer costs, and the cost management tools. For each service you know, ask what the cheaper alternative is and what you give up. Take a Domain 4 paper, then a mixed paper across all domains.
Week 6: full mocks and repair. Sit a full-length mock under exam conditions: 65 questions, 130 minutes, no notes. Review every question, including correct ones, fix your weakest topics over two or three days, then sit a second mock. See [how to use practice exams effectively](/blog/how-to-use-practice-exams-effectively).
Common traps
- Ignoring the qualifier. "Most cost-effective", "least operational overhead", "highest availability" and "minimal changes to the application" each point to a different answer among options that all work. Underline the qualifier before reading the options.
- Choosing self-managed when managed fits. When a question asks for the least operational effort, running software on EC2 is rarely right if a managed service (RDS, Fargate, DynamoDB) meets the need.
- Mixing up S3, EFS and EBS. EBS is block storage attached to one instance in one AZ (with limited Multi-Attach exceptions). EFS is a shared file system across instances and AZs. S3 is object storage accessed over an API. Many distractors swap these.
- Confusing Multi-AZ with read replicas. Multi-AZ deployments are for availability and failover; read replicas are for scaling reads. A question about surviving an AZ failure and one about read-heavy load need different answers.
- Security groups versus network ACLs. Security groups are stateful and allow-only, applied to resources; network ACLs are stateless, support deny rules and apply at subnet level. Blocking a specific IP address points to a network ACL.
- Partial answers on multiple response. Read how many options the question asks for and check each one on its own merits. AWS scores unanswered questions as wrong with no penalty for guessing, so never leave one blank.
How to practise
CertifyCloudx has original SAA-C03 practice questions written against the current exam guide, with explanations for every option. Each domain has papers of up to 25 questions (60 minutes per 25), and full-length timed mock exams run to the real exam's 130-minute limit. The free plan includes practice sets for every certification, up to 10 questions a day, with no card needed. You can read [how our practice questions are written](/blog/how-certifycloudx-practice-questions-are-written) for the method behind them.
Start with the [SAA-C03 practice questions](/certifications/aws-solutions-architect-associate-saa-c03).
Frequently asked questions
How difficult is SAA-C03?
It is an associate-level exam, and most candidates find it noticeably harder than Cloud Practitioner because every question is a design scenario with several workable answers. The challenge is breadth plus judgement: knowing many services and picking the one that best fits the stated constraint.
How long should I prepare for SAA-C03?
Six weeks of regular study suits most people with some AWS or IT background. If you use AWS daily, four weeks may be enough; if you are new to cloud, allow longer and consider taking Cloud Practitioner first, as AWS suggests for candidates without IT work experience.
Do I need another AWS certification first?
No. There is no prerequisite. AWS recommends at least one year of hands-on experience designing cloud solutions on AWS, and suggests that people without IT work experience earn the Cloud Practitioner certification first.
How long is the certification valid?
Three years. You can recertify by passing the latest version of the exam, or by earning AWS Certified Solutions Architect – Professional, which automatically recertifies the associate certification.
Are CertifyCloudx questions real SAA-C03 exam questions?
No. Every CertifyCloudx question is original and written against the public exam guide. Using leaked exam content breaks the AWS candidate agreement and can cost you the certification; see [why exam dumps put your certification at risk](/blog/why-exam-dumps-put-your-certification-at-risk).
Is there a penalty for guessing?
No. AWS scores unanswered questions as incorrect and applies no penalty for guessing, so answer every question. Fifteen of the 65 questions are unscored and are not identified.
CertifyCloudx is independent and not affiliated with Amazon Web Services. AWS Certified Solutions Architect – Associate is a trademark of its owner. All CertifyCloudx practice questions are original.